{"database": "press", "table": "releases", "rows": [["https://www.portman.senate.gov/newsroom/press-releases/senate-floor-portman-condemns-widespread-cyberattacks-calls-bipartisan", "On Senate Floor, Portman Condemns Widespread Cyberattacks, Calls for Bipartisan Efforts to Bolster Cybersecurity", "2020-12-18", "2020", "2020-12", "Republican", "Senate", "OH", "Rob Portman", "P000449", "www.portman.senate.gov", null, null, "legacy", "On Senate Floor, Portman Condemns Widespread Cyberattacks, Calls for Bipartisan Efforts to Bolster Cybersecurity\n \n      \n  \n\n          \n                          \n      December 18, 2020\n      \n  \n |     \n                          \n      Press Releases\n      \n  \n  \n    \n                  WASHINGTON, DC Today, U.S. Senator Portman Rob Portman (R-OH) strongly spoke out against the ongoing cyberattacks on our federal agencies, U.S. companies, and some state governments on the Senate floor. Earlier today, Portman, who will serve as the top Republican on Senate Homeland Security and Governmental Affairs Committee in the new Congress, condemned the cyberattacks and announced plans to hold hearings and work on bipartisan comprehensive cybersecurity legislation in the new year. \nPortman noted that these attacks demonstrate thevulnerabilitiesof our cyber defenses and the needfor bipartisan action in Congress to do more to equip the federal government to defend against and deter future cyberattacks. He highlighted the bipartisan report he issued last year as Chairman of the Permanent Subcommittee on Investigations warning of vulnerabilities at federal agencies to cyberattacks. Portman also spoke about his leadership in legislative efforts to strengthen the federal government cyber response.\nA transcript of his remarks can be found below and a video can be found here. \nSo 2020 has been a tough year. Let's face it. And unfortunately it looks like the challenges haven't ended. I came to the floor tonight primarily to talk about some shocking and disturbing news we just heard over the last few days. And that's that there has been a massive, highly sophisticated, and ongoing cyberattack that has compromised the networks of multiple federal agencies and the private sector. \nAccording to reports, for months now, months, hackers -- our intelligence experts think they are most likely connected with the Russian government in some way, that's what they tell us -- but these hackers have engaged in an espionage effort to access information at some of our biggest federal agencies that hold some of our most sensitive data, and our most sensitive and important national security secrets. Also again, many U.S. private companies were hacked as well. \nThese hackers are smart. They targeted some of these agencies that do handle things like national security, the State Department, for instance, the Department of Homeland Security, the Department of Energy and its Nuclear Security Administration. This is scary stuff. Others, like the National Institutes of Health, were hacked. Of course, they are closely involved with our work to respond to the COVID-19 pandemic, so also a lot of important, sensitive information could have been hacked. They are a treasure-trove of information. These are agencies that protect our homeland, promote our freedom abroad, and are on the front lines battling this pandemic. \nBut what we know today may be just the tip of the iceberg, we are told. Experts expect that the number of agencies, as well as a number of private companies victimized by this attack, will only continue to grow. The main IT monitoring platform believed to have been hacked was used across the government and by 33,000 private companies. Shockingly, we also know that FireEye, the preeminent cyber incident response firm, was also breached. So think about this. FireEye, which is a company that people call when they are hacked, was hacked. \nWe're still learning the details about this attack, but what we know is chilling. Federal investigators from the Cybersecurity and Infrastructure Security Agencies -- that's CISA -- under the Department of Homeland Security, the FBI, and also the Office of National Intelligence -- the ODNI -- are all working to determine how this happened, what the extent of it is, but it looks like the main vulnerability was through a SolarWinds platform, which is an IT monitoring platform, again, widely used by the government and the private sector to oversee the operation of other computer networks. \nThe hackers disguised their entry into these federal agencies' and companies' systems in a troubling and clever way. They exploited a vulnerability in a security patch sent out by SolarWinds to update its software. I want to emphasize that. The security patches that we all advocate to be installed as soon as possible to protect our networks as basic good cyber-hygiene was actually a security breach. This technique and the breadth of this hack are both unprecedented and it shows that the federal government is still far from where we need to be to handle the cybersecurity challenges of the 21st century. \nAs the Permanent Subcommittee on Investigations did in its investigation and report, these alarms that we have been raising over time are ones that we should have paid attention to. In 2019, last summer, Senator Carper and I issued a shocking report that detailed the unacceptable cybersecurity vulnerabilities in the federal government. Vulnerabilities that may very well have played a role in the extent of this breach. Our report looked back at how well federal agencies complied with basic cybersecurity standards over the past decade. Every agency we reviewed failed. And we know that four of those agencies, the Department of Homeland Security, the State Department, the Department of Agriculture, the Department of Health and Human Services, are among those that have been breached in this current cyberattack. \nThat report from the Permanent Subcommittee on Investigations made clear that federal agencies were a target for cyber criminals and other nation-state adversaries. In 2017 alone, federal agencies reported 35,277 cyber incidents. It's the most recent data we have. In one year, the number of cyber incidents in 2019 was a little bit less, 28,581. But 2020 will bring what is likely the biggest, most comprehensive breach across the federal government in our history. \nWe have also found we're not equipped to handle this threat. Many of the agencies we reviewed didn't even know what applications and platforms were operating on its systems. That begs the question -- how can you protect something if you don't even know what you need to protect? If federal agencies fail at meeting basic cyber standards, there is no way they are equipped to thwart the kind of sophisticated attack that apparently happened over the past several months. Here the attackers were meticulous and had a detailed understanding of how to evade intrusion detection practices and technologies, and because the federal agencies involved were unprepared, the attackers had ample time to cover their tracks, which means evaluating the extent of the damage and kicking them off our networks is going to be incredibly difficult and time consuming. Given how widespread this attack is and how much wider it's expected to become, it certainly seems like the federal government's current cyber resources are going to be spread incredibly thin. \nCongress and the executive branch have failed to prioritize cybersecurity and now we find ourselves vulnerable and exposed. We have to do better than this. This breach has to be a wake-up call for all of us. Over the years, I've worked across the aisle with Senator Peters, Senator Cornyn, Senator Hassan and others on legislation to beef up our federal government cyber capacities, including the Risk-Informed Spending for Cybersecurity Act, the Federal System Incident Response Act, the DHS Cyber Hunt and Incident Response Team Act, and others. We're proud of this legislation, but let's be honest. It wasn't enough. We need to do more. We need to not only defend our networks but go on the offense to deter nation states like Russia and non-state actors from even considering a future attack like this. That means there needs to be consequences for cyberattacks significant enough to prevent them from happening again, and a willingness to act preemptively when warranted. Congress has to take a hard look at the cybersecurity capabilities of our federal agencies. \nIn the next Congress, I will be the top Republican on the Senate Homeland Security and Governmental Affairs Committee, which means I will either serve as its chairman or its ranking member, depending on the outcome of a couple of races in Georgia. Senator Peters will be the chair if the Democrats take the majority. I will tell you here tonight, whether I'm chairman in January or him, we intend to hold in-depth hearings on cybersecurity. With what's happened, we will also, of course, focus on the origin, scope, and severity of this breach. Actually, three weeks ago, even before this attack was revealed, we met and decided to hold these cybersecurity hearings and we are already working on comprehensive legislation to improve our cyber defenses in the federal government going forward. We must now move with renewed sense of purpose and urgency to learn from this massive attack. We have got to remove these hackers from these systems and put in place protections to prevent it from happening again.\nAs this cyberattack has made clear, we have got to redouble our efforts to shore up our defenses. We are two decades into the 21st century, but most of the federal government legacy computer systems are from the 20th century. Federal agencies are simply behind the times when it comes to defending themselves against these threats posed in cyberspace. The government is trying to respond to sophisticated 21st century attacks with 20th century defenses. This attack has shown us the consequences of that and should be the catalyst for real bipartisan action here in the next Congress to better defend networks that contain sensitive personal information and other information critical to our economy, our health care, and the safety and security of all Americans.\n###", 1, "2026-03-30T12:14:52Z", "2026-03-30T12:14:52Z"]], "columns": ["url", "title", "date", "year", "month", "party", "chamber", "state", "member_name", "bioguide_id", "domain", "scraper", "source", "date_source", "text", "has_text", "collected_at", "updated_at"], "primary_keys": ["url"], "primary_key_values": ["https://www.portman.senate.gov/newsroom/press-releases/senate-floor-portman-condemns-widespread-cyberattacks-calls-bipartisan"], "units": {}, "query_ms": 0.8812390733510256, "source": "dwillis/congress-press", "source_url": "https://github.com/dwillis/congress-press", "license": "MIT", "license_url": "https://github.com/dwillis/congress-press/blob/main/LICENSE"}